FaceTime fraud number positioning method based on multi-source data

Through the FaceTime fraud number positioning method based on multi-source data, the machine learning model and triangular positioning algorithm are used to solve the problem of insufficient recognition and positioning accuracy of FaceTime fraud number recognition and positioning in the existing technology, and efficient and accurate fraud number recognition and positioning are achieved.

CN120075731APending Publication Date: 2025-05-30广州市申迪计算机系统有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510164296.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

It is difficult for the existing technology to effectively identify and locate frauds carried out by FaceTime, especially in complex urban environments, where the positioning accuracy is insufficient, and traditional prevention methods are passive and cannot be intervened in time.

Method used

The FaceTime fraud number positioning method based on multi-source data is adopted. By collecting operators' multi-source communication data, pre-processing and feature extraction, building behavioral feature indicators, training machine learning models, performing number classification, and combining base station information and MR data, triangular positioning algorithms are used for precise positioning.

Benefits of technology

It realizes accurate identification and high-precision positioning of FaceTime fraud numbers, with positioning accuracy up to 50 meters, improving the efficiency and accuracy of identifying and combating fraud dens.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075731A_ABST
    Figure CN120075731A_ABST
Patent Text Reader

Abstract

The invention relates to the field of mobile communication, in particular to a FaceTime fraud number positioning method based on multi-source data, and the method mainly comprises the steps: collecting the multi-source communication data of an operator; preprocessing the multi-source communication data, extracting features related to FaceTime fraud according to a preset rule, and constructing behavior feature indexes of the fraud; classifying numbers in the multi-source communication data based on the pre-trained machine learning model to obtain a target number; and acquiring base station information and MR data of the target number, positioning the target number based on a triangulation positioning algorithm, and outputting a positioning result. According to the method, after the mobile phone number of the domestic material supply gang is identified, the positioning precision of the target number is reduced to a range of 50 meters through triangulation positioning, accurate positioning data is provided for subsequent attack behaviors, and fraud sites can be quickly locked and attacked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of mobile communications, and in particular, to a method for locating FaceTime fraud numbers based on multi-source data. Background Art

[0002] With the rapid development of mobile Internet technology, telecom network fraud means have been constantly renovated. Among them, cases of fraud using the FaceTime function of Apple mobile phones occur frequently, bringing serious property losses and security risks to the majority of users.

[0003] When the existing telecom network fraud governance methods face FaceTime fraud, there are many challenges. First, the caller ID number of FaceTime voice and video calls can be arbitrarily modified, enabling fraud to easily bypass the traffic supervision of operators and increasing the difficulty of identification and prevention. Second, the international, diverse, and cross-regional nature of Internet network traffic makes it difficult for a single operator to conduct a full-coverage analysis of the traffic of fraud-related numbers, thus unable to detect and block fraud in a timely manner. In addition, traditional fraud prevention means for overseas calls, such as flash messages and SMS warnings, are often passive and lagging, and cannot effectively intervene before fraud occurs.

[0004] In terms of positioning accuracy, traditional positioning technologies, such as positioning based on base stations, often cannot meet the needs of combating FaceTime fraud due to the large coverage area of base stations. Especially in complex environments such as cities, the positioning error of base station positioning may reach several hundred meters or even more than one kilometer, which is far from enough for accurately combating fraud dens. Existing high-precision positioning technologies, such as the Global Navigation Satellite System (GNSS), although able to provide high-precision positioning services, will have greatly reduced positioning effects in indoor areas or areas with severe signal occlusion, and cannot meet the real-time and accurate positioning requirements.

[0005] Content of the Application

[0006] The present application provides a method for locating FaceTime fraud numbers based on multi-source data, which can accurately and real-time identify and locate the numbers of FaceTime fraud gangs.

[0007] To achieve the above object, the present application adopts the following technical solutions:

[0008] In a first aspect, the present application provides a method for locating FaceTime fraud numbers based on multi-source data, including:

[0009] Collecting multi-source communication data of operators;

[0010] Preprocess the multi-source communication data, extract the features related to FaceTime fraud according to the preset rules, and construct the behavioral feature indicators of fraud;

[0011] Obtain the positive and negative sample data sets, and train a machine learning model based on the behavioral feature indicators and the positive and negative sample data sets;

[0012] Classify the numbers in the multi-source communication data based on the pre-trained machine learning model to obtain the target numbers;

[0013] Obtain the base station information and MR data of the target numbers, locate the target numbers based on the triangulation algorithm, and output the location results.

[0014] In a preferred example of the present application, it can be further set that the obtaining the base station information and MR data of the target numbers, and locating the target numbers based on the triangulation algorithm includes:

[0015] Obtain the MR measurement report data of the target numbers under at least three base stations, and extract the signal strength information;

[0016] Based on the signal strength information, calculate the distances between the target numbers and each base station through the path loss model of the wireless signal;

[0017] Calculate the position coordinates of the target numbers based on each of the distances.

[0018] In a preferred example of the present application, it can be further set that the calculating the distances between the target numbers and each base station through the path loss model of the wireless signal based on the signal strength information, and calculating the position coordinates of the target numbers based on each of the distances includes:

[0019] Based on the signal strength information, use the path loss model of the wireless signal to calculate the distances between the transmission position of the target number and the three receiving base stations respectively, and obtain the first distance d 1 、the second distance d 2 、the third distance d 3 ;

[0020] Establish a system of equations to solve the coordinates (x, y) of the target position, and the system of equations is:

[0021] (x 1 -x) 2 +(y 1 -y) 2 =d 1 2 ;

[0022] (x 2 -x) 2 +(y 2-y) 2 = d 2 2 ;

[0023] (x 3 - x) 2 +(y 3 - y) 2 = d 3 2 。

[0024] In a preferred example of the present application, it can be further set that obtaining the positive and negative sample data sets, training a machine learning model based on the behavioral feature indicators and the positive and negative sample data sets, and classifying the numbers in the multi-source communication data based on the pre-trained machine learning model include:

[0025] Obtain the positive and negative sample data sets, label the positive and negative sample data sets according to the behavioral feature indicators to obtain a training set;

[0026] Train an XGBoost model based on the behavioral feature indicators and the training set;

[0027] During training, dynamically adjust the parameters of the XGBoost model for optimizing sample imbalance;

[0028] Classify the numbers in the multi-source communication data based on the pre-trained XGBoost model.

[0029] In a preferred example of the present application, it can be further set that the behavioral feature indicators at least include the number of times of using a specific software, the feature of inserting a SIM card into an Apple mobile phone terminal, and the number of interactions with a specific SMS port.

[0030] In a preferred example of the present application, it can be further set that it further includes:

[0031] Real-time monitor the target number, and collect the real-time multi-source communication data of the target number;

[0032] Dynamically update the training data of the machine learning model based on the real-time multi-source communication data;

[0033] Output the location coordinates of the target number to a data visualization system.

[0034] In a second aspect, the present application provides a FaceTime fraud number positioning device based on multi-source data, and the device includes:

[0035] A data acquisition module for collecting multi-source communication data of an operator;

[0036] A feature construction module for preprocessing the multi-source communication data, extracting features related to FaceTime fraud according to preset rules, and constructing behavioral feature indicators for fraud;

[0037] A model training module for training a machine learning model based on the behavioral feature indicators and the preprocessed multi-source communication data;

[0038] A classification module for classifying the numbers in the multi-source communication data based on the pre-trained machine learning model to obtain target numbers;

[0039] A positioning module for obtaining base station information and MR data of the target number, positioning the target number based on a triangulation algorithm, and outputting a positioning result.

[0040] In a third aspect, the present application provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the steps of the FaceTime fraud number positioning method based on multi-source data as described in any one of the above are implemented.

[0041] In a fourth aspect, the present application provides a computer-readable storage medium, on which a program is stored. When the program is executed by a processor, the FaceTime fraud number positioning method based on multi-source data as described in any one of the above is implemented.

[0042] In a fifth aspect, the present application provides a computer program product, including computer instructions, which implement the steps of the FaceTime fraud number positioning method based on multi-source data as described in any one of the above when executed by a processor.

[0043] In summary, compared with the prior art, the beneficial effects brought by the technical solutions provided in the embodiments of the present application at least include:

[0044] Compared with the prior art, the method of the present application obtains multi-source communication data, such as DPI, call, and text message record data of operators. Based on these data, a feature engineering is constructed and a machine learning model is trained, which can accurately and quickly identify the mobile phone numbers registered by domestic material supply gangs for Apple IDs, accurately distinguish normal users and members of fraud gangs, and improve the accuracy and efficiency of identification. Moreover, after identifying the mobile phone numbers of domestic material supply gangs, the present application further combines MR (Measurement Report) data for accurate positioning, and reduces the positioning accuracy of the target number to within a range of 50 meters through triangulation, providing accurate positioning data for subsequent cracking-down actions, and helping to quickly lock and crack down on fraud dens. Description of the Drawings

[0045] Figure 1 Flowchart of a method for locating FaceTime fraud numbers based on multi-source data provided by an embodiment of the present application.

[0046] Figure 2 Schematic diagram of fraud techniques in the application scenario of a method for locating FaceTime fraud numbers based on multi-source data provided by an embodiment of the present application.

[0047] Figure 3 Schematic diagram of triangulation for a method for locating FaceTime fraud numbers based on multi-source data provided by an embodiment of the present application.

[0048] Figure 4 Module diagram of a device for locating FaceTime fraud numbers based on multi-source data provided by an embodiment of the present application. Detailed implementation manners

[0049] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0050] In an embodiment of the present application, a method for locating FaceTime fraud numbers based on multi-source data is provided. Please refer to Figure 1 as shown, the method includes:

[0051] S100: Collect multi-source communication data of the operator.

[0052] Specifically, this embodiment is applied to a scenario such as Figure 2 as shown. First, the fraud gang publishes the "betting odds" work start requirements in the Telegram group in advance, and contacts the domestic material supply gang in advance to make an appointment for matters such as the start time, rental duration, and fee settlement method of the fraud materials. Second, the domestic material supply gang registers the SIM card to activate the FaceTime function. Third, when starting work, the domestic material supply gang will provide a complete set of information such as Apple ID to the overseas fraud gang through the Telegram group, and cooperate to provide verification codes to help the overseas gang successfully log in to the Apple ID. This is the fraud technique of renting an Apple ID overseas for FaceTime fraud.

[0053] The multi-source communication data includes DPI data, call signaling data, SMS signaling data, and SMS bill data. The DPI data includes but is not limited to time, number, URL of the target website visited by the user, domain name of the external website, host name HOST, software information used, etc. The call signaling data includes call start time, calling number, called number, ringing duration, call duration, calling IMEI, called IMEI, calling base station, called base station, etc. The SMS signaling data includes start time, calling number, called number, calling base station, called base station, process status identifier, etc. The SMS bill data includes short message bill type, user number, called number, operator code, service code, information fee, number of information items, user location, sending time, etc.

[0054] S200: Preprocess the multi-source communication data, extract features related to FaceTime fraud according to preset rules, and construct behavioral feature indicators of fraud.

[0055] Specifically, the collected data is preprocessed, including data cleaning, format conversion and other preprocessing, and then feature extraction is performed on the number behavior. The constructed behavior feature indicators include but are not limited to Table 1:

[0056]

[0057]

[0058]

[0059]

[0060] Table 1

[0061] S300: Acquire a positive and negative sample data set, and train a machine learning model based on the behavior feature index and the positive and negative sample data set;

[0062] Specifically, we obtain positive and negative sample data sets, label them based on the above-mentioned characteristic behavior indicators, and construct training set data for the machine learning model. Positive samples are numbers used by domestic material supply gangs to register Apple IDs. They are obtained in two ways: on the one hand, the numbers shown on FaceTime caller IDs reported by victims; on the other hand, the number cards corresponding to domestic material supply gangs captured by the public security departments of various provinces are obtained as positive samples. Negative samples are non-fraudulent numbers. Numbers located in and belonging to this area are obtained through signaling call records and DPI data, which are used as negative samples.

[0063] Among them, the dataset used contains more than 30,000 labeled samples, and the ratio of positive to negative samples is approximately 1:10. Each sample includes multiple features as mentioned above. The dataset is divided into two parts: the training set (80%) and the test set (20%). The training set is used for model training and parameter tuning, while the test set is used for the final model evaluation.

[0064] After the positive and negative samples are labeled, select a suitable machine learning algorithm for model training according to actual needs and data characteristics.

[0065] The machine learning model includes but is not limited to XGBoost. XGBoost is an efficient gradient boosting decision tree algorithm. It can handle large-scale datasets and has the advantage of parallel computing (able to automatically utilize the multi-threading of the CPU for parallel processing). It can be used for the modeling and identification of numbers of domestic material supply gangs.

[0066] The steps for XGBoost model training and parameter selection are as follows:

[0067] (1) To comprehensively evaluate the model performance, select four key indicators to examine the model performance from different dimensions and reveal its applicability and effectiveness in practical applications. The key indicators include:

[0068] Accuracy: As a basic indicator, it measures the overall proportion of correct predictions by the model. For example, if 95 out of 100 samples are correctly classified, whether normal or fraudulent. This means that the overall judgment of the model is 95% correct.

[0069] Precision: Focuses on the accuracy of the model's predictions for the fraud category, that is, the proportion of predicted samples that are actually fraud among the total predictions. For example, if 90 out of 100 suspected frauds are predicted to be true, then the precision is 90%.

[0070] False Positive Rate (1 - Precision): In the anti-fraud scenario, this indicator focuses on measuring the proportion of predictions that are fraud but are actually not fraud. In the above example, the false positive rate is 10%.

[0071] Recall: Also known as the recall rate, it measures the ability of the model to detect real fraud samples, that is, the proportion of samples that are actually fraud and are correctly predicted. For example, if there are a total of 100 fraud samples and the model finds 90 of them, the recall rate is 90%, emphasizing the comprehensiveness of the model in finding all fraud behaviors.

[0072] These indicators are used in combination to more comprehensively evaluate the performance of the model.

[0073] (2) The selection and tuning of model parameters are based on a series of predefined experiments, and the performance of the model under different parameter configurations is evaluated through cross-validation. The following parameters are mainly adjusted: num_boost_round (number of boosting rounds), scale_pos_weight (weight ratio of positive and negative samples), gamma (parameter for post-pruning), eta (learning rate), min_child_weight (minimum weight of child nodes), subsample (ratio of sub-samples), and colsample_bytree (column sampling ratio when constructing trees). In addition, random_state is set to 2024 for all models to ensure the reproducibility of the results.

[0074] During the parameter tuning process, first, a part of the parameters are fixed (for example, eta, min_child_weight, subsample, and colsample_bytree are all set to 0.2, 4, 0.9, and 0.9), and then other parameters are carefully adjusted. For example, the values of num_boost_round are tested with 500, 800, 1000, etc. to explore the impact of different numbers of boosting rounds on the model performance. scale_pos_weight is adjusted from 300 to 600 to examine the ability of the model to handle imbalanced data with different weight ratios of positive and negative samples.

[0075] Through parameter selection and model training, not only are the model parameters optimized, but also the robustness and efficiency of the model in handling imbalanced data are ensured.

[0076] S400: Classify the numbers in the multi-source communication data based on the pre-trained machine learning model to obtain target numbers.

[0077] Specifically, the target numbers are the numbers of the domestic material supply gang in the FaceTime fraud scenario.

[0078] S500: Obtain the base station information and MR data of the target numbers, locate the target numbers based on the triangulation algorithm, and output the location results.

[0079] Specifically, there is only base station information in conventional signaling call records or DPI data. The longitude and latitude information of the base station can be obtained by associating with the wireless base station engineering parameter table. However, due to the large coverage range of 4 / 5G base stations (the coverage radius of 5G base stations is about 300 - 500 meters, and the coverage radius of 4G base stations is about 1 - 3 kilometers), it is necessary to further associate with the longitude and latitude information of wireless MR to improve the positioning accuracy.

[0080] MR (Measurement Report) is the raw network data measured by the user terminal. The measurement report carries relevant information about the uplink and downlink radio links, including RSCP, ISCP, BLER, transmit power, etc.

[0081] The measurement report data mainly comes from the physical layer and RLC layer of the UE and Node B, as well as the measurement reports calculated by the RNC during the radio resource management process. The original measurement data is either reported to the OMC-R for storage in the form of statistical data after statistical calculation (which can be implemented on the RNC or OMC-R), or directly reported to the OMC-R for storage in the form of sample data.

[0082] The operator's big data platform stores MR data. For a certain number, if this number reports wireless MR data under three base stations, then based on the relationship established between the signal propagation model and distance, the method of triangulation can be used for in-depth positioning of the target location.

[0083] The triangulation method is as Figure 3 shown. There are three base stations in the figure, and the circles are the wireless signal ranges of the base stations. Assume that a certain domestic material supply gang number has 4 / 5G Internet access behavior under the above three base stations. Then, the signal strength of the number in the 4 / 5G Internet access wireless MR under the 3 4 / 5G base stations can be obtained. Through the path loss model of the wireless signal, the first distance d between the transmitter and the receiver is obtained using the signal strength 1 , the second distance d 2 , the third distance d 3 , and the following three equations are obtained:

[0084] (x 1 -x) 2 +(y 1 -y) 2 =d 1 2 ;

[0085] (x 2 -x) 2 +(y 2 -y) 2 =d 2 2 ;

[0086] (x 3 -x) 2 +(y 3 -y) 2 =d 3 2 ;

[0087] In summary, the detailed position coordinates of the domestic material supply gang numbers (target numbers) can be solved, so as to obtain the MR longitude and latitude with higher accuracy. Through the positioning of the MR longitude and latitude, we can narrow the position accuracy of the domestic material supply gang numbers to within a range of 50 meters, greatly improving the positioning accuracy and providing accurate positioning data for assisting in the crackdown.

[0088] In this embodiment, the beneficial effects at least include:

[0089] Compared with the traditional identification method for Internet fraud users, through in-depth excavation of the full chain analysis of domestic material supply gangs registering Apple IDs and providing Apple IDs to help overseas fraud gangs log in to Apple IDs in the FaceTime fraud scenario, this embodiment extracts effective fraud features and combines with the XGBoost machine learning algorithm to achieve accurate identification and high-precision positioning of the domestic material supply gang numbers in FaceTime fraud, filling the gaps in the identification and crackdown of domestic material supply gang numbers in FaceTime fraud in the existing technology.

[0090] Multi-source communication data is obtained, such as DPI, call, text message and other record data of operators. Based on these data, a feature engineering is constructed and a machine learning model is trained, which can accurately and quickly identify the mobile phone numbers of domestic material supply gangs registering Apple IDs, accurately distinguish normal users from fraud gang members, and improve the accuracy and efficiency of identification.

[0091] After identifying the mobile phone numbers of the domestic material supply gangs, further combine with MR (Measurement Report) data for accurate positioning. Through triangulation, the positioning accuracy of the target number is narrowed to within a range of 50 meters, providing accurate positioning data for subsequent crackdown actions and helping to quickly lock and crack down on fraud dens.

[0092] In some embodiments, obtaining the base station information and MR data of the target number and positioning the target number based on the triangulation algorithm includes:

[0093] Obtain the MR measurement report data of the target number under at least three base stations and extract the signal strength information;

[0094] Based on the signal strength information, calculate the distances between the target number and each base station through the path loss model of the wireless signal;

[0095] Calculate the position coordinates of the target number based on the distances.

[0096] In some embodiments, based on the signal strength information, calculating the distances between the target number and each base station through the path loss model of the wireless signal and calculating the position coordinates of the target number based on the distances includes:

[0097] Based on the signal strength information, use the path loss model of the wireless signal to calculate the distances between the transmission location of the target number and the three receiving base stations respectively, and obtain the first distance d 1 , the second distance d 2 , and the third distance d 3 ;

[0098] Establish a system of equations to solve the coordinates (x, y) of the target location. The system of equations is:

[0099] (x 1 - x) 2 +(y 1 - y) 2 = d 1 2 ;

[0100] (x 2 - x) 2 +(y 2 - y) 2 = d 2 2 ;

[0101] (x 3 - x) 2 +(y 3 - y) 2 = d 3 2 .

[0102] In some embodiments, the obtaining of the positive and negative sample datasets, training the machine learning model based on the behavioral feature indicators and the positive and negative sample datasets, and classifying the numbers in the multi-source communication data based on the pre-trained machine learning model includes:

[0103] Obtain the positive and negative sample datasets, label the positive and negative sample datasets according to the behavioral feature indicators, and obtain the training set;

[0104] Train the XGBoost model based on the behavioral feature indicators and the training set;

[0105] During training, dynamically adjust the parameter of the XGBoost model to optimize sample imbalance;

[0106] Classify the numbers in the multi-source communication data based on the pre-trained XGBoost model.

[0107] In some embodiments, the behavioral feature indicators at least include the number of times of using a specific software, the feature of inserting the SIM card into an Apple mobile phone terminal, and the number of interactions with a specific SMS port.

[0108] In some embodiments, it further includes:

[0109] Monitor the target number in real time, and collect the real-time multi-source communication data of the target number;

[0110] Dynamically update the training data of the machine learning model based on the real-time multi-source communication data;

[0111] Output the position coordinates of the target number to the data visualization system.

[0112] This application also provides a FaceTime fraud number positioning device based on multi-source data. Please refer to Figure 4 As shown, the device includes:

[0113] A data collection module 100 for collecting multi-source communication data of the operator;

[0114] A feature construction module 200 for preprocessing the multi-source communication data, extracting features related to FaceTime fraud according to preset rules, and constructing behavior feature indicators of fraud;

[0115] A model training module 300 for obtaining positive and negative sample data sets, and training a machine learning model based on the behavior feature indicators and the positive and negative sample data sets;

[0116] A classification module 400 for classifying the numbers in the multi-source communication data based on the pre-trained machine learning model to obtain a target number;

[0117] A positioning module 500 for obtaining the base station information and MR data of the target number, positioning the target number based on the triangulation algorithm, and outputting the positioning result.

[0118] The functions of each module in the above FaceTime fraud number positioning device based on multi-source data correspond to the steps in the embodiments of the above FaceTime fraud number positioning method based on multi-source data, and their functions and implementation processes will not be elaborated here one by one.

[0119] This application also provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the FaceTime fraud number positioning method based on multi-source data as described in any of the above embodiments.

[0120] The present application also provides a computer-readable storage medium, on which a program is stored. Herein, the computer-readable storage medium refers to a carrier for storing data, which may include, but is not limited to, floppy disks, optical discs, hard disks, flash memories, USB flash drives, and / or memory sticks, etc. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. For the working process, working details, and technical effects of the computer-readable storage medium provided in this embodiment, reference may be made to the embodiments of a method for locating FaceTime fraud numbers based on multi-source data in the foregoing text, which will not be elaborated herein.

[0121] The application also provides a computer program product, including computer instructions, which, when executed by a processor, implement the steps of the method for locating FaceTime fraud numbers based on multi-source data as described in any of the foregoing embodiments.

[0122] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the foregoing embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it may include the processes of the embodiments of the foregoing methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application may include non-volatile and / or volatile memories. The non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. The volatile memory may include random access memory (RAM) or an external cache. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM).

[0123] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification. The above embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.

Claims

1. A method for locating FaceTime fraud numbers based on multi-source data, characterized in that: include: Collect multi-source communication data from operators; Preprocessing the multi-source communication data, extracting features related to FaceTime fraud according to preset rules, and constructing behavioral feature indicators of fraud; Obtaining positive and negative sample data sets, and training a machine learning model based on the behavioral feature indicators and the positive and negative sample data sets; Classifying the numbers in the multi-source communication data based on the pre-trained machine learning model to obtain target numbers; The base station information and MR data of the target number are obtained, the target number is located based on a triangulation positioning algorithm, and the positioning result is output.

2. The method for locating FaceTime fraud numbers based on multi-source data according to claim 1, characterized in that: The step of acquiring the base station information and MR data of the target number and locating the target number based on a triangulation positioning algorithm includes: Obtaining MR measurement report data of the target number under at least three base stations, and extracting signal strength information; Based on the signal strength information, the distance between the target number and each base station is calculated by a path loss model of the wireless signal; The location coordinates of the target number are calculated based on each of the distances.

3. The method for locating FaceTime fraudulent numbers based on multi-source data according to claim 2, characterized in that: The calculating, based on the signal strength information, the distance between the target number and each base station by using a path loss model of the wireless signal, and calculating the location coordinates of the target number based on each of the distances, includes: Based on the signal strength information, the distances between the transmitting position of the target number and three receiving base stations are calculated using a path loss model of wireless signals to obtain a first distance d1, a second distance d2, and a third distance d3; A set of equations is established to solve the coordinates (x, y) of the target position. The set of equations is: (x1-x) 2 +(y1-y) 2 =d1 2 ; (x2-x) 2 +(y2-y) 2 =d2 2 ; <h2 style=";text-align:left;direction:ltr">(x3-x)<h2 style=";text-align:left;direction:ltr"> 2 <h2 style=";text-align:left;direction:ltr"> +(y3-y)<h2 style=";text-align:left;direction:ltr"> 2 <h2 style=";text-align:left;direction:ltr"> =d3<h2 style=";text-align:left;direction:ltr"> 2 <h2 style=";text-align:left;direction:ltr"> 。 4. The method for locating FaceTime fraudulent numbers based on multi-source data according to claim 3, characterized in that: The obtaining of positive and negative sample data sets, training a machine learning model based on the behavior feature indicators and the positive and negative sample data sets, and classifying numbers in the multi-source communication data based on the pre-trained machine learning model includes: Acquire positive and negative sample data sets, and label the positive and negative sample data sets according to the behavioral feature indicators to obtain a training set; Training an XGBoost model based on the behavioral feature index and the training set; During training, dynamically adjusting the parameters of the XGBoost model to optimize sample imbalance; The numbers in the multi-source communication data are classified based on the pre-trained XGBoost model.

5. The method for locating FaceTime fraud numbers based on multi-source data according to claim 1, characterized in that: The behavioral characteristic indicators include at least the number of times specific software is used, the characteristics of the SIM card being inserted into an Apple mobile phone terminal, and the number of interactions with a specific SMS port.

6. The method for locating FaceTime fraud numbers based on multi-source data according to claim 1, characterized in that: Also includes: Performing real-time monitoring on the target number and collecting real-time multi-source communication data of the target number; Dynamically updating the training data of the machine learning model based on the real-time multi-source communication data; The location coordinates of the target number are output to a data visualization system.

7. A FaceTime fraud number location device based on multi-source data, characterized in that: include: Data collection module, used to collect multi-source communication data of operators; A feature construction module, used to pre-process the multi-source communication data, extract features related to FaceTime fraud according to preset rules, and construct behavioral feature indicators of fraud; A model training module, used to obtain positive and negative sample data sets, and train a machine learning model based on the behavior feature indicators and the positive and negative sample data sets; A classification module, configured to classify numbers in the multi-source communication data based on the pre-trained machine learning model to obtain target numbers; The positioning module is used to obtain the base station information and MR data of the target number, locate the target number based on the triangulation positioning algorithm, and output the positioning result.

8. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the FaceTime fraud number locating method based on multi-source data as described in any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a program, wherein when the program is executed by the processor, the method for locating a FaceTime fraud number based on multi-source data as described in any one of claims 1 to 6 is implemented.

10. A computer program product comprising computer instructions, characterized in that When executed by a processor, the computer instructions implement the steps of the method for locating a FaceTime fraud number based on multi-source data as described in claims 1 to 6.